The Answer in 60 Seconds

A Property All Risks (PAR) or business package policy may carry a small "Cyber" sub-limit or carve-back, or may exclude cyber loss outright. Standalone Cyber insurance is a dedicated policy with materially broader cover, with first-party (your costs) and third-party (claims against you) sections, plus access to insurer panel forensics, legal, breach counsel, and PR. A PAR carve-back may respond only to physical damage, such as a fire or explosion that results from damage to electronic data (NMA2914) or from a non-malicious cyber incident (LMA5400); standalone Cyber responds to the full incident lifecycle including business interruption, data breach response, ransomware payment (where covered), regulatory defence, and third-party liability. Property policies can expressly exclude cyber events: MSIG's SUMO package, for example, excludes any "Cyber Loss" from its property sections, so any cyber cover left in a PAR is a narrow add-back, not standalone protection.

The Sourced Detail

Founders who see "Cyber" as a line item on the property package may assume they are covered and discover at incident time that the sub-limit covers only part of the response cost, if it responds at all.

Why PAR policies have cyber exclusions in the first place

After significant losses from major cyber incidents (NotPetya 2017, WannaCry 2017, SolarWinds 2020), the global insurance market repriced cyber risk. Following Lloyd's Market Bulletin Y5258 (4 July 2019), the Lloyd's Market Association published model property and marine cyber clauses on 13 November 2019 (LMA5400 to LMA5403) to help the market give clarity of cyber cover under first-party property policies. The older Institute Cyber Attack Exclusion Clause (CL380) is an Institute of London Underwriters clause dated 10 November 2003.

The Institute Cyber Attack Exclusion Clause (CL380) reads, in paraphrase:

"This Policy does not cover loss, damage, liability, cost, or expense directly or indirectly caused by, contributed to by, resulting from, or arising out of the use or operation, as a means for inflicting harm, of any computer, computer system, computer software programme, malicious code, computer virus, computer process, or any other electronic system."

The exclusion typically applies regardless of whether the cyber event is the proximate cause or a contributing cause. Some wordings carve back specific perils (e.g. fire resulting from a cyber event remains covered as fire damage); others apply the exclusion broadly.

What a typical PAR Cyber sub-limit actually covers

Where a PAR or business package policy has a small Cyber section or carve-back, check whether its cover is:

  • Limited to physical damage caused by cyber events (e.g. data centre fire triggered by malware) - the carve-back from the broader cyber exclusion
  • First-party costs only - costs you incur, not third-party claims
  • A low sub-limit, which may sit far below the cost of responding to an incident
  • No incident response panel - you call your IT vendor, who is unlikely to be experienced in regulatory notification or breach counsel
  • No specialist forensics - meaning evidence preservation may be amateur
  • No third-party liability - claims by affected individuals or business partners are uncovered
  • No ransomware coverage, with extortion payments excluded
  • No business interruption coverage, leaving downtime cost uncovered

What standalone Cyber insurance covers

A dedicated Cyber policy is structured around the modern incident lifecycle. Standard sections:

First-party cover (your costs):

  • Forensic investigation costs
  • Legal advice on regulatory obligations (PDPA, sectoral regulations)
  • Breach notification costs (PDPC, affected individuals)
  • Credit monitoring for affected individuals
  • Public relations / crisis communications
  • Ransomware extortion payment (subject to sanctions screening and policy conditions)
  • System restoration costs
  • Business interruption from cyber events (lost revenue during downtime)
  • Contingent business interruption (when your supplier is hit)
  • Data restoration and reconstruction costs

Third-party cover (claims against you):

  • Privacy and data breach liability
  • Network security liability
  • Defamation and content injury (some policies)
  • Regulatory investigations and proceedings
  • Payment Card Industry (PCI) fines and assessments

Service access:

  • 24/7 incident hotline
  • Pre-vetted panel forensics
  • Pre-vetted panel legal and breach counsel
  • Pre-vetted panel PR
  • Threat intelligence and post-incident remediation guidance

The dollar value of the services accessed via panel can exceed the dollar value of the indemnity payment.

Limit and pricing comparisons

PAR sub-limit:

  • Limit: as set in the package wording
  • Premium impact: depends on the package; check whether the cyber item is included as standard or charged as an extension
  • Indicates: minimal cover; not designed for material incidents

Standalone Cyber for SMEs:

  • Limits: chosen at placement and stated in the schedule
  • Annual premium: varies widely with revenue, sector, security posture, prior claims; obtain comparative quotes
  • Includes panel access and incident response infrastructure

Industries where the gap matters most

For these sectors, relying on a PAR sub-limit can leave the business under-insured:

  1. SaaS and software companies - customer data exposure plus business interruption
  2. Healthcare - patient data with PDPA significant-harm category implications
  3. Financial services and fintech - MAS regulatory expectations plus PDPA
  4. E-commerce and retail with payment processing - PCI scope plus customer data
  5. Professional services with sensitive client data - law, accounting, financial planning, HR consulting
  6. Manufacturers with operational technology (OT) - production line stoppage from cyber events
  7. Logistics and supply chain - system outage cascading to operational disruption
  8. Schools and education providers - minor-related personal data with elevated PDPA significance

The Cybersecurity (Amendment) Act 2024 angle

The Cybersecurity (Amendment) Act 2024 - with key provisions in force from 31 October 2025 - expanded cyber incident reporting requirements for owners of Critical Information Infrastructure (CII). For non-CII SMEs, the headline obligation remains the PDPA Section 26D 3-day breach notification. For CII operators, the new framework adds 2-hour reporting obligations.

The insurance implications: cover for regulatory investigation, defence and (where insurable) penalties differs between cyber policies, so a comparative read matters.

When the PAR sub-limit might actually be enough

For a narrow set of SMEs, the PAR sub-limit can be operationally sufficient:

  • Single-employee businesses with no customer personal data
  • Brick-and-mortar retail with minimal digital footprint
  • Pre-revenue startups with no production systems
  • Businesses where the entire IT estate is third-party SaaS and the SaaS providers carry the breach risk under contract

For these profiles, the cost of standalone Cyber may exceed the realistic exposure.

Common Mistakes / What Goes Wrong

  1. Reading "Cyber" on the PAR schedule and assuming it's adequate. It can be a narrow carve-back from a cyber exclusion, not a standalone product.
  2. Treating IT support contract as cyber insurance. Your IT vendor fixes systems; they don't pay PDPC fines or third-party damages.
  3. Calling the IT vendor before the cyber insurer. Burns panel-forensics cover under standalone Cyber.
  4. Buying standalone Cyber but not understanding the panel. The panel is the cover. If you don't use them, you may not be reimbursed.
  5. Letting Cyber lapse between policies. Cyber liability cover is written on a claims-made basis in wordings such as AIG's CyberEdge, and its first-party response cover applies to breaches first discovered during the policy period, so incidents notified or discovered after a lapse may be uncovered.
  6. Ignoring retroactive dates. Pre-policy breaches (often unknown when the policy is bought) may be excluded entirely.
  7. Assuming Cyber covers all data breaches. Some policies exclude employee data breaches, social engineering fraud, or specific incident types - read the wording.

What This Means for Your Business

For Singapore SMEs evaluating cyber cover:

  1. Read your current PAR / business package wording. Find the cyber exclusion clause and the Cyber section sub-limit. This is your current baseline.

  2. Map your exposure. Customer data records held, employee data, payment processing scope, system criticality, downtime cost per day.

  3. Get a standalone Cyber quote. Not as a "should I switch" exercise but as a comparison reference. The gap between what the PAR covers and what standalone covers becomes visible only in side-by-side review.

  4. Assess panel access. For SMEs without dedicated security teams, the panel access alone can justify the premium - you cannot easily access top-tier forensics or breach counsel on a one-off basis at incident time.

  5. Review at every business change. New product line, new customer base, new geographic market, M&A, regulatory licence - all change cyber exposure.

Where a PAR carries a cyber sub-limit or carve-back, it is a narrow add-back, not the primary protection against ransomware, supply chain attacks, regulatory enforcement or third-party claims.

Questions to Ask Your Adviser

  1. What does my current PAR policy say about cyber events - is there an exclusion, a carve-back sub-limit, or both?
  2. What is the sub-limit on the PAR Cyber section, and what does it actually respond to (physical damage only, first-party costs, third-party liability)?
  3. For my business profile, what would standalone Cyber cost, and what limit and panel would it provide?
  4. Does the Cyber policy cover ransomware payment, regulatory investigation defence, business interruption, and contingent BI?
  5. What is the retroactive date, and does it provide cover for breaches that may have occurred but not yet been discovered?

Related Information

Published 4 May 2026. Source verified 4 May 2026.